Weaknesses of type CWE-476

2,333 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2025-31163MEDIUMfig2dev segmentation faultEPSS 0.2%CVE-2025-55651MEDIUMA NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows attackers to cause EPSS 0.2%CVE-2024-0078MEDIUMCVEEPSS 0.2%CVE-2026-1991MEDIUMlibuvc UVC Descriptor device.c uvc_scan_streaming null pointer dereferenceEPSS 0.2%CVE-2022-49889MEDIUMring-buffer: Check for NULL cpu_buffer in ring_buffer_wake_waiters()EPSS 0.2%CVE-2024-23808MEDIUMArkcompiler ets frontend has an out-of-bounds read vulnerabilityEPSS 0.2%CVE-2022-49300MEDIUMnbd: fix race between nbd_alloc_config() and module removalEPSS 0.2%CVE-2022-49864MEDIUMdrm/amdkfd: Fix NULL pointer dereference in svm_migrate_to_ram()EPSS 0.2%CVE-2025-31202MEDIUMA null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4EPSS 0.2%CVE-2025-21980MEDIUMsched: address a potential NULL pointer dereference in the GRED scheduler.EPSS 0.2%CVE-2020-36789MEDIUMcan: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ contextEPSS 0.2%CVE-2026-24515LOWIn libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.EPSS 0.2%CVE-2023-28327MEDIUMA NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly alloEPSS 0.2%CVE-2021-29564LOWNull pointer dereference in `EditDistance`EPSS 0.2%CVE-2025-3010MEDIUMKhronos Group glslang Intermediate.cpp isConversionAllowed null pointer dereferenceEPSS 0.2%CVE-2024-12227MEDIUMMSI Dragon Center IOCTL NTIOLib_X64.sys MmUnMapIoSpace null pointer dereferenceEPSS 0.2%CVE-2023-2898—There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privilegEPSS 0.2%CVE-2021-29565LOWNull pointer dereference in `SparseFillEmptyRows`EPSS 0.2%CVE-2021-29541LOWNull pointer dereference in `StringNGrams`EPSS 0.2%CVE-2021-29572LOWReference binding to nullptr in `SdcaOptimizer`EPSS 0.2%